@Jonathan Telling, Thanks for posting in Q&A. From your description, I know we have changed the Automatic enrollment from All to some. But the device still auto enrolls into Intune.
Here I have some suggestions:
1, For the MDM auto enrollment, please confirm if we change it under MDM user scope of Microsoft Intune. Please change to none to see if the result will be different.
2, When unenroll the device from Intune and Microsoft Entra ID, please ensure the devices records in both Intune and Microsoft Entra ID portal are removed. In addition, please clean the enrollment registry information under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Enrollments.
In addition, please check the device information on the device side Setting->Accounts->Access work or school, to see which account has info button which means enroll into Intune and confirm if it is enrolled into the previous tenant or IE tenant.
Please try the above suggestion and if there's any update, feel free to let us know.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.